36517Third-party advisory
http://secunia.com/advisories/36517 CVE-2009-3252
Rock Band CMS 0.10 - 'news.php' Multiple SQL Injections (2)
Record summary
CVE-2009-3252 has a selected CVSS score of 7.5; EIP currently links 2 catalogued exploits.
Description
Multiple SQL injection vulnerabilities in news.php in Rock Band CMS 0.10 allow remote attackers to execute arbitrary SQL commands via the (1) year and (2) id parameters.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 2
Proofs of concept
2Catalogued exploits
ExploitDBRock Band CMS 0.10 - 'news.php' Multiple SQL Injections (2)ExploitDB exploitby AffixNot analyzed1 file
ExploitDBRock Band CMS 0.10 - 'news.php' Multiple SQL Injections (1)ExploitDB exploitby AffixNot analyzed1 file
References
59553exploit
http://www.exploit-db.com/exploits/9553 ADV-2009-2494vdb entry
http://www.vupen.com/english/advisories/2009/2494 bandcms-news-sql-injection(52940)vdb entry
https://exchange.xforce.ibmcloud.com/vulnerabilities/52940 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2009-3252